TL;DR: Mullvad VPN AB, the Gothenburg-based VPN provider, published the State Mass Surveillance entry of its Why Privacy Matters series on June 25, 2026. The 4,000-word primer walks through the United States (FISA Section 702, PRISM Upstream and Downstream, XKeyscore, the NSA Utah data center, the FBI and CIA's commercial data-broker workaround), Europe (UK Tempora, the Five Eyes and Fourteen Eyes alliance, the EU Chat Control proposal, France's AI video surveillance, Pegasus spyware against journalists and human-rights defenders), and the authoritarian world (Russia's SORM and Moscow Safe City facial-recognition grid, Iran's SIAM mobile-network monitoring, China's Great Firewall, Police Cloud, voice-print collection, and 2 million state-employed public-opinion analysts). Mullvad's structural point: democratic and authoritarian states are converging on the same mass-surveillance model, and the consumer-facing age-verification infrastructure FIRE's Sarah McLaughlin named in her 'papers, please' essay the same day is one slice of the same global pattern. The piece lands in the same week as Cory Doctorow's pluralistic.net op-ed, Anthropic's July 8 Persona Identities rollout, and the June 26 Daily Surveillance Briefing tie-back to all of them.
The Premise: Two Types of Mass Surveillance, One Convergence
Mullvad's editorial opens by splitting the surveillance world in two: commercial surveillance, which it covers in a separate piece in the same series, and state mass surveillance, which is the subject of the June 25 primer. The company has been writing about the second since 2009, the year it was founded in Gothenburg, Sweden, on the principle that mass surveillance infringes on the human rights free societies are built on and is also ineffective against the problems it is claimed to solve.[1]
The message to states is the same now as it was seventeen years ago: "There's a difference between surveillance and mass surveillance. Don't get involved with the latter: don't carry out mass surveillance on your population or that of other countries. Use targeted surveillance if there's a suspicion of a crime, in a proportional way and via independent court decisions."[1]
The structural argument, made explicit across the 4,000 words, is that even a large share of what looks like targeted state surveillance is global in origin and converges on the same institutional pattern. The user-facing identity-verification infrastructure that Sarah McLaughlin names in her June 25 FIRE essay as the new legislative infrastructure of surveillance is one slice of the same architecture. So is the Anthropic July 8 Persona Identities rollout. So is the EU Chat Control proposal Mullvad itself names in the European section. The primer ties the institutional pieces to the consumer-facing pieces in a single map.[1]
United States: FISA Section 702, PRISM, and the Utah Data Center
The longest section of the primer is the United States, and it is also the most operationally detailed. Mullvad starts with the institutional fact: American mass surveillance is possible because of Section 702 of the Foreign Intelligence Surveillance Act, a law the US renews every five years, and which the NSA and FBI use to monitor people without an individual court order. The law was justified after the September 11, 2001 attacks on the pretext of tracking foreign terrorists, but in practice the way Section 702 is written, and the way the internet is constructed, it sweeps in American citizens as well.[1]
Two operational details are central. The first is the Upstream and Downstream structure of the PRISM program. Upstream taps the internet backbone directly; Downstream collects from the servers of providers who are required by the law to hand over customer data. The second is the XKeyscore program, a search tool that, in the words of the 2013 Snowden documents published by The Guardian, covers "nearly everything a typical user does on the internet." XKeyscore lets NSA analysts run hard searches (against an IP address or email address) or soft searches (against a keyword) without a court order and without a superior's approval inside the NSA.[2] The volume is structural. The Guardian reported in January 2014 that the NSA was collecting 200 million text messages a day from around the world, untargeted, as part of a program called Dishfire.[3]
The Verizon metadata order, the first document Snowden handed to Laura Poitras and Glenn Greenwald in that Hong Kong hotel room in 2013, was a Section 215 bulk-collection order against Verizon Business Network Services that the Guardian published on June 6, 2013, forcing the first public confirmation that the US was collecting the call detail records of millions of Americans in bulk.[4] Inside the agency, the posture was explicit. At a 2013 public conference, CIA chief technology officer Ira "Gus" Hunt told the audience "we try to collect everything and hang onto it forever."[5] A senior Defense Department official, in language Mullvad quotes, told Pentagon employees: "We want our people to understand: they should make no assumptions about anonymity. You are not anonymous on this planet at this point in our existence. Everyone is trackable, traceable, discoverable to some degree."[1]
The physical infrastructure is on the same scale. The NSA Bluffdale Utah Data Center, which James Bamford first reported in Wired in March 2012, was built specifically to store the bulk-collection output of these programs at a single site.[6] The European and allied surveillance partners ride the same backbone. Le Monde reported in October 2013 that the NSA was intercepting 70 million French phone calls per month; the Guardian reported the same month that the NSA had monitored the calls of world leaders, including German chancellor Angela Merkel's mobile phone.[7][8]
The CIA was inside the same network. The Vault 7 leak published by WikiLeaks in 2017 showed the CIA had built a custom toolkit to hack consumer phones, computers, and smart TVs; Motherboard's Joseph Cox reported that the CIA's consumer-tech partners were not denying the leak this time. Samsung's fine print on voice recognition, quoted by Mullvad, told users that "if your spoken words include personal or other sensitive information, that information will be among the data captured and transmitted to a third party through your use of Voice Recognition."[1]
The Data-Broker Workaround: Buy the Surveillance, Skip the Fourth Amendment
Mullvad's most operationally specific section is the workaround. Once the political consensus after Snowden made direct bulk collection of American phone records more expensive, the US agencies started buying the same information from commercial data brokers. The data is the same. The legal exposure is different.[1]
Senator Ron Wyden, one of the most vocal critics of the practice, has publicly released documents confirming that the NSA buys American internet browsing records, and has called on the intelligence community to stop buying US data obtained unlawfully from data brokers, in violation of a recent FTC order.[9] Mullvad quotes the explanation for why the workaround is structurally attractive: when the agencies buy the data, they do not have to claim that American citizens "happened to be caught up in surveillance of foreign threats."[1]
The commercial data is rich enough that the practice has reshaped how the agencies operate. A Wired investigation found the Pentagon used the ad-tech ecosystem to find targets in Vladimir Putin's inner circle, quoting a US government consultant who described the ad-tech ecosystem as "the largest information-gathering enterprise ever conceived by man."[10] Former CIA director Michael Morell, quoted in a Wall Street Journal essay by Byron Tau, said it more plainly: "The information that is available commercially would kind of knock your socks off. If we collected it using traditional intelligence methods, it would be top secret-sensitive. And you wouldn't put it in a database, you'd keep it in a safe."[11]
Wyden's 2023 letter to the Director of National Intelligence, which Mullvad cites, made the constitutional point bluntly: the CIA is not permitted to carry out this kind of data collection under the US Constitution, even though it does it anyway under the Section 702 exemption. Buying the data is the workaround.[1]
The 2024 Reauthorization: Two Years, Not Five, and a Wider Net
The structural story behind the data-broker workaround is the 2023-2024 fight over the Section 702 reauthorization. The 2024 renewal, the fourth since the program was first authorized in 2008, was unusually contested. The House of Representatives failed to pass an extension three times and was forced to delay the decision until spring 2024. The EFF tracked the amendment fight: the biggest proposed amendment would have forced agencies to obtain court approval before monitoring American citizens, and another would have ended "abouts collection" of communications where a foreign target was merely mentioned.[12]
Both failed. What passed was a two-year extension, half the usual length, and an expansion of the list of "covered providers" that the agencies can compel to hand over data. ZwillGen's analysis is that the new definition is broad enough to reach any organization that handles customer communications.[13] The New York Times reported on April 16, 2024 that the language could even include "anyone with physical access to a target's communications infrastructure, such as routers."[14]
Wyden called the expansion "dramatic and terrifying." Edward Snowden's response, on the platform then known as Twitter, was: "The NSA is taking over the internet."[1] Instead of a step back from post-9/11 surveillance architecture, the 2024 reauthorization expanded the architecture in exactly the way the civil-liberties lobby had warned about.[1]
Europe: Tempora, the Five Eyes, and the Chat Control Vote
The European section opens with the same backbone. The UK GCHQ's Tempora program, the Wired UK explainer details, intercepts the fiber-optic cables that carry traffic between the US and Europe, with the same effect as the US Upstream collection at the other end. The Guardian reported in June 2013 that 850,000 NSA employees had access to the British system, and that the GCHQ-NSA partnership was processing 600 million "telephone events" and other traffic per day across 200 fiber-optic cables.[15] Snowden called Tempora "the largest program of suspicionless surveillance in human history."[15] Internal GCHQ training material, surfaced in the same leak, used the line "you are in an enviable position: have fun and make the most of it."[15]
Five Eyes and Fourteen Eyes are the formal alliance names. The original Five Eyes pact, between the US, UK, Canada, Australia, and New Zealand, dates to the Second World War. The expanded Fourteen Eyes group, which adds Belgium, Denmark, France, Germany, Italy, the Netherlands, Norway, Spain, and Sweden, was disclosed in the Snowden documents. Mullvad's editorial note is sharp: it is a Swedish company, in a Fourteen Eyes country, and that has no impact on its users, because the geographic location of the VPN provider is irrelevant when the underlying traffic crosses multiple Fourteen Eyes jurisdictions on the physical cables. The legal jurisdiction that matters is the country whose laws govern the VPN provider's logging. Sweden's laws are good for that. The "outside Fourteen Eyes" marketing claim is, Mullvad writes, ignorant and dishonest.[1]
The Chat Control section is where the European piece collides with the consumer-facing identity-verification infrastructure. Mullvad, which has its own Chat Control position page, calls the proposal a "total prohibition on private communication" that would mean "mass surveillance on a level that would even make the NSA jealous."[16] The Politico scoop on June 24, 2026, in which European Parliament President Roberta Metsola pushed EU leaders to advance the message-scanning regulation despite the Parliament's earlier rejection of it, is the proximate event that makes the Mullvad framing part of the same news cycle. The 60-plus civil-society organizations opposing Chat Control, including EFF, EDRi, and the Mullvad editorial team, frame the regulation as the functional destruction of end-to-end encryption in the EU.[1]
The rest of the European section is short and pointed. France has been rolling out AI video surveillance in public spaces, with critics arguing the Paris 2024 Olympics were the wedge. Hungary, per the Freedom House 2022 country report, has installed "black boxes" that give the state direct access to ISP networks, and therefore to user internet behavior, without a court decision. The UK Online Safety Bill pushes the same end-to-end encryption friction from a different angle. Across Europe and beyond, NSO Group's Pegasus spyware has been used by multiple state and state-adjacent actors to target dissidents, political activists, and journalists, including high-profile cases against human-rights defenders.[17]
The Courts Have Been Clear. The Policies Have Not Changed.
The structural read between Mullvad's European and authoritarian sections is that the surveillance architecture has been ruled illegal more than once, in the same jurisdictions that continue to operate it. The European Court of Human Rights, in a 2021 ruling, the Guardian reported, found that the UK's GCHQ mass-data-sharing regime under Tempora was incompatible with the conditions required for a democratic society.[18] In September 2020, a US court ruled that the NSA's mass surveillance of hundreds of millions of people was unlawful and unconstitutional.[19] And Politico has tracked how the EU's highest court has repeatedly ruled that mass data retention is illegal, including in the decisions that have defined the limits of EU member-state surveillance laws.[20]
None of those rulings has stopped the underlying programs. The argument the courts have made is consistent: mass surveillance is incompatible with the legal frameworks democratic states are supposed to operate inside. The argument the states have made in response is consistent: the programs are necessary, the rulings will be worked around, and the next vote on the next renewal will be the moment the architecture is expanded. Mullvad's framing is the moral one: "Human rights are there to protect people against the state. And it's also important to remember that rights are something you also have to fight for."[1]
The Pattern: One Architecture, Many Fronts
The structural read across the 4,000 words is that the consumer-facing identity-verification infrastructure, the institutional foreign-intelligence collection architecture, the court-ruled-but-still-operating European bulk-collection programs, and the openly authoritarian surveillance systems are all running the same underlying model. The model is: collect everything, store it, link it, and repurpose it. The use case varies. The infrastructure does not.[1]
Three of the cases the Mullvad primer touches on are also live SOS stories this week. The FIRE "papers, please" essay Sarah McLaughlin published the same day names the consumer-facing version of the same architecture: the age-verification mandate is the wrapper, the identity database is the prize. Anthropic's July 8 Persona Identities rollout is the producer-side version, the same database linked to a frontier-model consumer product. Cory Doctorow's June 23 pluralistic.net op-ed is the consumer-rights critique of the same infrastructure, with a regulatory-reform ask. The Mullvad primer is the institutional context the other three land inside.[1]
Mullvad's editorial close is the one the structural argument hinges on. The same week the FIRE essay names the database as the prize, the Anthropic privacy policy operationalizes the producer-side version, and the EU Chat Control proposal would extend the architecture to every encrypted message in the Union, the 4,000-word primer is the institutional reminder. Democratic and authoritarian states are competing to be best at mass surveillance. They are running similar systems. The infrastructure is the through-line, and the next time the next renewal vote comes up, it is the architecture the vote is about.
Sources
- Mullvad VPN AB: Democratic and authoritarian countries are competing to see which of them can carry out mass surveillance most and best (worst), the State Mass Surveillance entry in the Why Privacy Matters series, June 25, 2026. https://mullvad.net/en/why-privacy-matters/state-mass-surveillance
- The Guardian, James Ball, Julian Borger, Glenn Greenwald: Revealed: how US and UK spy agencies defeat internet privacy and security, September 6, 2013. https://www.theguardian.com/world/2013/sep/05/nsa-gchq-encryption-codes-security (also https://www.theguardian.com/world/2013/jul/31/nsa-top-secret-program-online-data)
- The Guardian, James Ball: NSA collects millions of text messages daily in 'untargeted' global sweep, January 16, 2014. https://www.theguardian.com/world/2014/jan/16/nsa-collects-millions-text-messages-daily-untargeted-global-sweep
- The Guardian, Glenn Greenwald: NSA collecting phone records of millions of Verizon customers daily, June 6, 2013. https://www.theguardian.com/world/2013/jun/06/nsa-phone-records-verizon-court-order
- YouTube: GigaOM Structure:Data 2013, with CIA Chief Technology Officer Ira 'Gus' Hunt on the "collect it all" approach. https://www.youtube.com/watch?v=GUPd2uMiXXg
- Wired, James Bamford: The NSA Is Building the Country's Biggest Spy Center (Watch What You Say), March 15, 2012. https://www.wired.com/2012/03/ff-nsadatacenter/
- Le Monde, Jacques Follorou and Martin Untersinger: France in the NSA's crosshairs, October 21, 2013. https://www.lemonde.fr/technologies/article/2013/10/21/france-in-the-nsa-s-crosshair-phone-networks-under-surveillance_3499741_651865.html
- The Guardian, James Ball: NSA monitored calls of 35 world leaders after obtaining phone numbers, October 24, 2013. https://www.theguardian.com/world/2013/oct/24/nsa-surveillance-world-leaders-calls
- Senator Ron Wyden press release: Wyden Releases Documents Confirming the NSA Buys Americans' Internet Browsing Records, Calls on Intelligence Community to Stop Buying US Data Obtained Unlawfully from Data Brokers, Violating Recent FTC Order, January 25, 2024. https://www.wyden.senate.gov/news/press-releases/wyden-releases-documents-confirming-the-nsa-buys-americans-internet-browsing-records-calls-on-intelligence-community-to-stop-buying-us-data-obtained-unlawfully-from-data-brokers-violating-recent-ftc-order
- Wired, Byron Tau: How the Pentagon Learned to Use Targeted Ads to Find Its Targets, February 27, 2024. https://www.wired.com/story/how-pentagon-learned-targeted-ads-to-find-targets-and-vladimir-putin/
- Wall Street Journal, Byron Tau: U.S. Spy Agencies Know Our Secrets. They Bought Them, February 27, 2024. https://www.wsj.com/politics/national-security/u-s-spy-agencies-know-our-secrets-they-bought-them-791e243f
- Electronic Frontier Foundation, Shahid Buttar: Bad Amendments to Section 702 Have Failed. Now What Happens Next, April 12, 2024. https://www.eff.org/deeplinks/2024/04/bad-amendments-section-702-have-failed-now-what-happens-next
- ZwillGen: FISA Reform Bill: 702 Surveillance, April 19, 2024. https://www.zwillgen.com/law-enforcement/fisa-reform-bill-702-surveillance/
- The New York Times, Charlie Savage: In Intelligence Bill, Expansion of Surveillance Power Is Annexed in Dead of Night, April 16, 2024. https://www.nytimes.com/2024/04/16/us/fisa-surveillance-bill-program.html
- The Guardian, James Ball: GCHQ taps fibre-optic cables for massive intelligence haul, June 21, 2013. https://www.theguardian.com/uk/2013/jun/21/gchq-cables-secret-world-communications-nsa
- Mullvad VPN: Chat Control position page. https://mullvad.net/chatcontrol
- The Guardian: Pegasus project investigations, July 2021 onwards. https://www.theguardian.com/news/series/pegasus-project
- The Guardian, Owen Bowcott: GCHQ's mass data sharing violated right to privacy, court rules, May 25, 2021. https://www.theguardian.com/uk-news/2021/may/25/gchqs-mass-data-sharing-violated-right-to-privacy-court-rules
- The Guardian, Spencer Ackerman: NSA mass surveillance exposed by Snowden was illegal, court rules, September 3, 2020. https://www.theguardian.com/us-news/2020/sep/03/edward-snowden-nsa-surveillance-guardian-court-rules
- Politico, Laurens Cerulus: Top EU court strikes down bulk data retention, October 6, 2020. https://www.politico.eu/article/data-retention-europe-mass-surveillance/
- Freedom House: Freedom on the Net 2022, Countering Authoritarian Overhaul of the Internet. https://freedomhouse.org/report/freedom-net/2022/countering-authoritarian-overhaul-internet#Tracking
- Wired, Andy Greenberg: How a Russian Faces Surveillance Network Uses AI, December 7, 2021. https://www.wired.com/story/moscow-safe-city-ntechlab/
- The Washington Post, Isabelle Khurshudyan, Pavel Khlebnikov, Mary Ilyushina: How Russia uses facial recognition to suppress dissent, April 16, 2021. https://www.washingtonpost.com/world/europe/russia-facial-recognition-surveillance-navalny/2021/04/16/4b97dc80-8c0a-11eb-a33e-da28941cb9ac_story.html
- The New York Times, Anton Troianovski: How Investigative Reporters in Russia Cracked the Code of the Surveillance State, February 21, 2021. https://www.nytimes.com/2021/02/21/business/media/probiv-investigative-reporting-russia.html
- Human Rights Watch: China: Police 'Big Data' Systems Violate Privacy, Target Dissent, November 19, 2017. https://www.hrw.org/news/2017/11/19/china-police-big-data-systems-violate-privacy-target-dissent
- Freedom House: China country report, Freedom on the Net 2022. https://freedomhouse.org/country/china/freedom-net/2022
- The Intercept, Sam Biddle: Iran's Smartphone Protest Crackdown, October 28, 2022. https://theintercept.com/2022/10/28/iran-protests-phone-surveillance/
- The Register, Jessica Lyons: Egypt caught spying on regime's critics via smartphones, October 4, 2019. https://www.theregister.com/2019/10/04/egypt_smartphone_spying/
- Amnesty International: Morocco: Human Rights Defenders Targeted by NSO Group's Spyware, October 9, 2019. https://www.amnesty.org/en/latest/research/2019/10/morocco-human-rights-defenders-targeted-with-nso-groups-spyware/